Privacy Policy
A single policy covering both Cinderella mobile applications — the Client app used to book cleaning services and the Provider app used by professional cleaners and their teams to offer services on our platform.
This Privacy Policy explains how Schwarzschild Group Limited (“we”, “us”, “our”),
registered at 58 New Bedford Road, LUTON – LU1 1SH, United Kingdom (GB), email office@schwarzschildgroup.com, processes personal data when you use the Cinderella Client and Cinderella Provider mobile applications. Both Apps are covered by this policy; where a specific data category applies only to one App, we say so next to the relevant heading.
We act as the controller for the personal data described below and comply with the EU General Data Protection Regulation (GDPR) and applicable national laws in Romania, Germany and Hungary. For the formal compliance framework — legal bases, international-transfer safeguards and detailed procedures for exercising your rights — please see our GDPR compliance notice.
01Data we collect
1.1 Account and identity
- Email address and password (stored hashed on our servers).
- First name, last name, country code, preferred language.
- Phone number, verified via a one-time password (OTP) sent by SMS.
-
In the Provider App additionally: whether you operate
solo or as a team manager, and – if applicable,
the declared size of your team.
1.2 Business and tax data — Provider App only
Because the Provider App is a professional tool, providers must supply
during registration:
- VAT number.
- Company or trade-registry registration number.
- Billing address (which may differ from the base of operation).
1.3 Identity and certification documents
To use certain features, you may be asked to upload:
-
A photograph of a government-issued identity document and your
personal identification number (both Apps, when identity verification
is required). -
Any professional certifications required to offer cleaning services
in your market (Provider only).
Documents are transmitted to our backend over an encrypted connection,
are stored with access restricted to authorised verification staff,
and are marked with a verification status. When a document is rejected,
the reason is returned to you inside the App.
1.4 Profile photo
An optional profile picture uploaded from your camera or photo library.
1.5 Location data
When you use location-based features the App requests
foreground access to your device’s precise GPS
coordinates. Coordinates are reverse-geocoded to a human-readable
address and sent to our backend.
-
In the Client App, location is used to set the address for a service
booking and to display nearby available services. -
In the Provider App, location is used to set the provider’s
base of operation, to show nearby job offers, and — for
team managers — to set the base of operation of team members.
We do not collect background location and we do not continuously track
your device.
Recent addresses you have used are cached in encrypted device storage
on your device for your convenience.
1.6 Service preferences — Provider App only
Providers choose which services (e.g. residential, office,
deep-cleaning tasks) they are willing to accept at each of their
registered locations. These preferences are stored on our backend and
used to match providers with compatible jobs.
1.7 Communications
-
Chat messages, images and metadata (sender name, sender identifier,
timestamp) exchanged with the other party of a job or with our
support team. -
Emails you send us at
office@schwarzschildgroup.com.
Chat messages are stored in Google Firebase Firestore.
1.8 Payment and billing data
Both Apps use a subscription model — in the Client App to access
booking features, in the Provider App to access the platform and
receive job offers. In both cases we hold:
- Card metadata only: the last four digits, brand (e.g. Visa/Mastercard)
- Subscription status, last and next billing dates, price and currency.
Full payment card data never touches the App and is not stored on
our servers.
Card payments are processed by our payment provider,
Stripe, whose privacy notice applies to the card data
you enter
(
privacy notice
).
1.9 Device and technical data
-
A push-notification device token issued by Firebase Cloud Messaging
and a composite device identifier used to route notifications. -
Diagnostic attributes attached to crash reports: device brand,
device model, device type, App version, build number and bundle
identifier. - Crash stack traces and error context.
02Third-party service providers
The following processors act on our behalf for both Apps. Data is
transmitted over encrypted connections and processed under contractual
data-protection terms.
| Provider | Purpose | Data shared |
|---|---|---|
| Google Firebase Authentication | Sign-in tokens | User identifier, custom auth token |
| Google Firebase Cloud Messaging | Push notification delivery | Device push token, notification payloads |
| Google Firebase Firestore | Real-time chat storage | Chat messages, image references, sender identifier, timestamps |
| Google Firebase Crashlytics | Crash and error diagnostics | Crash reports and device attributes |
| Google Maps SDK & Google Places API | Map display and address autocomplete | Approximate coordinates, address search queries |
| Expo (reverse geocoding) | Convert coordinates to a readable address | Latitude and longitude |
| Stripe | Subscription and card payment processing |
Card data entered with the provider, billing metadata, invoicing information |
| Gateway API | Delivering phone verification SMS | Phone number, one-time code |
03Retention
We keep personal data only for as long as it is needed for the purpose
for which it was collected, or for as long as we are required to keep
it by law (for example, tax and invoicing obligations). When you delete
your account, your personal data is removed after a short grace period,
except for records we are legally obliged to retain.
04Your rights
4.1 Your rights at a glance
Under the GDPR you have the right to access, correct, delete, restrict,
port and object to the processing of your personal data, and to
withdraw consent for any permission granted at the OS level.
For the formal procedures, response times and how to exercise each
right, please see our
GDPR compliance notice
or email
office@schwarzschildgroup.com
.
4.2 Deleting your account
You can delete your account at any time from within the App under
Profile → My Account → Delete Account. Your account is placed
in a grace period during which you can cancel the deletion from the
same screen; after the grace period the account and associated personal
data are removed.
05Device permissions
Both Apps request the same set of operating-system permissions on iOS
and Android. The table below shows how each permission is used in each
App.
| Permission | Client App usage | Provider App usage |
|---|---|---|
| Location (while using the App) |
Show your address on the map and select the correct service location. |
Set your base of operation, display nearby jobs, and adjust team members’ base locations. |
| Camera | Take photos for your profile picture and identity documents. |
Take photos for your profile picture, identity documents and certifications. |
| Photo library |
Choose existing photos for your profile picture, identity documents and chat. |
Choose existing photos for your profile picture, identity documents, certifications and chat. |
| Notifications | Deliver push notifications about your jobs and chats. |
Deliver push notifications about job offers, chats and team assignments. |
| Calendar | Add scheduled jobs to your calendar (optional). | Add scheduled jobs to your calendar (optional). |
| Reminders (iOS only) | Set reminders for upcoming jobs (optional). | Set reminders for upcoming jobs (optional). |
| Internet | Communicate with our backend and third-party services. | Communicate with our backend and third-party services. |
06Security
- All communication with our backend uses HTTPS with modern TLS.
-
Authentication uses short-lived JWT access tokens and refresh tokens
stored in the OS Keychain / Keystore via the platform’s secure-storage
APIs. -
Access to identity documents, certifications, business data and
subordinate records on our backend is restricted to authorised
personnel only.
07Cookies, analytics and advertising
Neither App uses cookies, advertising identifiers (AAID / IDFA),
third-party analytics SDKs or advertising.
The only diagnostic data we collect is the crash telemetry described
in 1.9.